PDA

View Full Version : Dual SHA-1/SHA-2 code-signing on legacy Windows operating systems...



NewsArchive
02-03-2016, 04:08 AM
All,

Today, I had 14 SHA-1/SHA-2 dual code-signing support requests in my Inbox.
At least 7 developers tried dual code-signing on their Windows XP machines,
3 developers were using Windows 7, one developer was still on SetupBuilder
8.

To use your SHA-2 based code-signing certificate for dual SHA-1/SHA-2
signing you need:

1. SetupBuilder 10.

2. Windows 8.x or Windows 10.

3. SignTool.exe version 6.2.9200.16384 or later.

You can use the following tool to install SignTool 10.0.10240.16384:
http://www.lindersoft.com/forums/showthread.php?47076-Testers-needed!-SignTool-V10-Download-Tool&p=86090#post86090

Note: I tested SignTool 10.0.10240.16384 on Windows 8.0 and it worked fine
(see attached screenshot).

4. Microsoft Capicom installed and registered.

You can use the following tool to install Capicom:
http://www.lindersoft.com/forums/showthread.php?29427-Problem-compiling&p=53010#post53010

Here is the SB10 Tips & Tricks #1: Dual SHA-1/SHA-2 code-signing
http://www.lindersoft.com/forums/showthread.php?46908

Friedrich

--
Friedrich Linder
Lindersoft | SetupBuilder | www.lindersoft.com
954.252.3910 (within US) | +1.954.252.3910 (outside US)

--SetupBuilder "point. click. ship"
--Helping You Build Better Installations
--Create Windows 10 ready installations in minutes
--Official COMODO Code Signing and SSL Certificate Partner

NewsArchive
02-03-2016, 09:23 AM
Quick side note: Windows Server 2008 R2 also causes dual SHA-1/SHA-2
code-signing trouble! Windows Server 2012 R2 works fine out of the box.

So what you need is:

1. SetupBuilder 10.
2a. Windows 8.x or Windows 10 -or-
2b. Windows Server 2012 R2 or Windows Server 2016.
3. SignTool.exe version 6.2.9200.16384 or later.
4. Microsoft Capicom installed and registered.

I am still working on "Everything You Always Wanted to Know About
SHA-1/SHA-2 Code-Signing* (*But Were Afraid to Ask)".

Friedrich

--
Friedrich Linder
Lindersoft | SetupBuilder | www.lindersoft.com
954.252.3910 (within US) | +1.954.252.3910 (outside US)

--SetupBuilder "point. click. ship"
--Helping You Build Better Installations
--Create Windows 10 ready installations in minutes
--Official COMODO Code Signing and SSL Certificate Partner

NewsArchive
02-03-2016, 09:23 AM
Friedrich Linder wrote:
>
> I am still working on "Everything You Always Wanted to Know About SHA-1/SHA-2
> Code-Signing* (*But Were Afraid to Ask)".
>
You're AWESOME Friedrich!

Larry

NewsArchive
02-03-2016, 11:26 AM
Sweet.

Jeff Slarve
www.jssoftware.com
Twitter free since Jan 11, 2016
I'll search help files & Google for you.

Grammar troll's, are the worse.